Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough rights to create webhooks (mostly administrators) can drop the database. This is fixed in iTop 2.7.13 and 3.2.2 by verifying callback signature.
References
| Link | Resource |
|---|---|
| https://github.com/Combodo/iTop/security/advisories/GHSA-55q8-mfxr-pq4j | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-11-10 22:15
Updated : 2025-11-21 13:37
NVD link : CVE-2025-49145
Mitre link : CVE-2025-49145
CVE.ORG link : CVE-2025-49145
JSON object : View
Products Affected
combodo
- itop
CWE
CWE-863
Incorrect Authorization
